Skip to content

chore(deps): bump the actions-deps group with 10 updates#678

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/actions-deps-efda34c57d
Open

chore(deps): bump the actions-deps group with 10 updates#678
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/actions-deps-efda34c57d

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 1, 2026

Bumps the actions-deps group with 10 updates:

Package From To
step-security/harden-runner 2.14.1 2.15.0
tj-actions/changed-files 47.0.1 47.0.4
taiki-e/install-action 2.67.18 2.68.15
actions/upload-artifact 6.0.0 7.0.0
github/codeql-action 4.32.0 4.32.4
docker/build-push-action 6.18.0 6.19.2
anchore/scan-action 7.3.1 7.3.2
actions/attest-build-provenance 3.2.0 4.1.0
iarekylew00t/verified-bot-commit 2.1.2 2.1.6
anchore/sbom-action 0.22.1 0.23.0

Updates step-security/harden-runner from 2.14.1 to 2.15.0

Release notes

Sourced from step-security/harden-runner's releases.

v2.15.0

What's Changed

Windows and macOS runner support

We are excited to announce that Harden Runner now supports Windows and macOS runners, extending runtime security beyond Linux for the first time.

Insights for Windows and macOS runners will be displayed in the same consistent format you are already familiar with from Linux runners, giving you a unified view of runtime activity across all platforms.

Full Changelog: step-security/harden-runner@v2.14.2...v2.15.0

v2.14.2

What's Changed

Security fix: Fixed a medium severity vulnerability where outbound network connections using sendto, sendmsg, and sendmmsg socket system calls could bypass audit logging when using egress-policy: audit. This issue only affects the Community Tier in audit mode; block mode and Enterprise Tier were not affected. See GHSA-cpmj-h4f6-r6pq for details.

Full Changelog: step-security/harden-runner@v2.14.1...v2.14.2

Commits

Updates tj-actions/changed-files from 47.0.1 to 47.0.4

Release notes

Sourced from tj-actions/changed-files's releases.

v47.0.4

What's Changed

Full Changelog: tj-actions/changed-files@v47.0.3...v47.0.4

v47.0.3

What's Changed

Full Changelog: tj-actions/changed-files@v47.0.2...v47.0.3

v47.0.2

What's Changed

Full Changelog: tj-actions/changed-files@v47.0.1...v47.0.2

Changelog

Sourced from tj-actions/changed-files's changelog.

Changelog

47.0.4 - (2026-02-17)

🔄 Update

  • Release-tagger action to version 6.0.6 (#2801) (7dee1b0) - (Tonye Jack)

47.0.3 - (2026-02-17)

🔄 Update

  • Release-tagger action to version 6.0.0 (#2800) (28b28f6) - (Tonye Jack)

⚙️ Miscellaneous Tasks

  • deps: Bump github/codeql-action from 4.31.10 to 4.32.2 (#2790) (875e6e5) - (dependabot[bot])

47.0.2 - (2026-02-09)

🚀 Features

  • Add support for excluding symlinks and fix bug with commit not found (#2770) (8c4da28) - (Tonye Jack)

🐛 Bug Fixes

🔄 Update

  • Updated README.md (#2771)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@​users.noreply.github.com> (7d5bbf4) - (github-actions[bot])

  • Updated README.md (#2768)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@​users.noreply.github.com> (b3bb1f8) - (github-actions[bot])

  • Update README.md (c6a5847) - (Tonye Jack)

⚙️ Miscellaneous Tasks

  • deps: Bump actions/setup-node from 6.1.0 to 6.2.0 (#2766) (8cba46e) - (dependabot[bot])
  • deps-dev: Bump @​types/node from 25.0.0 to 25.2.2 (#2793) (925972f) - (dependabot[bot])
  • deps: Bump @​stdlib/utils-convert-path from 0.2.2 to 0.2.3 (#2795) (a98754b) - (dependabot[bot])
  • deps: Bump actions/checkout from 6.0.1 to 6.0.2 (#2777) (9c13e73) - (dependabot[bot])
  • deps-dev: Bump @​types/lodash from 4.17.21 to 4.17.23 (#2759) (16d791c) - (dependabot[bot])
  • deps-dev: Bump eslint-plugin-jest from 29.11.0 to 29.12.1 (#2756) (8e056de) - (dependabot[bot])
  • deps: Bump github/codeql-action from 4.31.7 to 4.31.10 (#2761) (078e2bc) - (dependabot[bot])
  • Update matrix-example.yml (#2752) (2f2f6cf) - (Tonye Jack)
  • Update dist (#2769) (8262acc) - (Tonye Jack)
  • deps: Bump @​actions/core from 2.0.0 to 2.0.2 (#2757) (daf9d2d) - (dependabot[bot])

... (truncated)

Commits
  • 7dee1b0 update: release-tagger action to version 6.0.6 (#2801)
  • 28b28f6 update: release-tagger action to version 6.0.0 (#2800)
  • 875e6e5 chore(deps): bump github/codeql-action from 4.31.10 to 4.32.2 (#2790)
  • 8cba46e chore(deps): bump actions/setup-node from 6.1.0 to 6.2.0 (#2766)
  • 925972f chore(deps-dev): bump @​types/node from 25.0.0 to 25.2.2 (#2793)
  • a98754b chore(deps): bump @​stdlib/utils-convert-path from 0.2.2 to 0.2.3 (#2795)
  • 9c13e73 chore(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#2777)
  • caee9d9 fix: Update test.yml (#2781)
  • 16d791c chore(deps-dev): bump @​types/lodash from 4.17.21 to 4.17.23 (#2759)
  • 8e056de chore(deps-dev): bump eslint-plugin-jest from 29.11.0 to 29.12.1 (#2756)
  • Additional commits viewable in compare view

Updates taiki-e/install-action from 2.67.18 to 2.68.15

Release notes

Sourced from taiki-e/install-action's releases.

2.68.15

  • Update mise@latest to 2026.2.23.

  • Update prek@latest to 0.3.4.

  • Update cargo-binstall@latest to 1.17.6.

2.68.14

  • Update wasm-bindgen@latest to 0.2.114.

  • Update typos@latest to 1.44.0.

2.68.13

  • Update uv@latest to 0.10.7.

  • Update mise@latest to 2026.2.22.

  • Update cargo-lambda@latest to 1.9.1.

2.68.12

  • Update tombi@latest to 0.7.33.

  • Update mise@latest to 2026.2.21.

2.68.11

  • Update wasmtime@latest to 42.0.1.

  • Update protoc@latest to 3.34.0.

  • Update dprint@latest to 0.52.0.

2.68.10

  • Update mise@latest to 2026.2.20.

  • Update wasm-bindgen@latest to 0.2.113.

  • Update uv@latest to 0.10.6.

2.68.9

  • Update wasmtime@latest to 42.0.0.

  • Update wasm-bindgen@latest to 0.2.112.

  • Update uv@latest to 0.10.5.

2.68.8

  • Update cargo-nextest@latest to 0.9.129.

  • Update mise@latest to 2026.2.19.

... (truncated)

Changelog

Sourced from taiki-e/install-action's changelog.

Changelog

All notable changes to this project will be documented in this file.

This project adheres to Semantic Versioning.

[Unreleased]

[2.68.15] - 2026-02-28

  • Update mise@latest to 2026.2.23.

  • Update prek@latest to 0.3.4.

  • Update cargo-binstall@latest to 1.17.6.

[2.68.14] - 2026-02-28

  • Update wasm-bindgen@latest to 0.2.114.

  • Update typos@latest to 1.44.0.

[2.68.13] - 2026-02-27

  • Update uv@latest to 0.10.7.

  • Update mise@latest to 2026.2.22.

  • Update cargo-lambda@latest to 1.9.1.

[2.68.12] - 2026-02-26

  • Update tombi@latest to 0.7.33.

  • Update mise@latest to 2026.2.21.

[2.68.11] - 2026-02-26

  • Update wasmtime@latest to 42.0.1.

  • Update protoc@latest to 3.34.0.

  • Update dprint@latest to 0.52.0.

[2.68.10] - 2026-02-25

... (truncated)

Commits

Updates actions/upload-artifact from 6.0.0 to 7.0.0

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

Commits

Updates github/codeql-action from 4.32.0 to 4.32.4

Release notes

Sourced from github/codeql-action's releases.

v4.32.4

  • Update default CodeQL bundle version to 2.24.2. #3493
  • Added an experimental change which improves how certificates are generated for the authentication proxy that is used by the CodeQL Action in Default Setup when private package registries are configured. This is expected to generate more widely compatible certificates and should have no impact on analyses which are working correctly already. We expect to roll this change out to everyone in February. #3473
  • When the CodeQL Action is run with debugging enabled in Default Setup and private package registries are configured, the "Setup proxy for registries" step will output additional diagnostic information that can be used for troubleshooting. #3486
  • Added a setting which allows the CodeQL Action to enable network debugging for Java programs. This will help GitHub staff support customers with troubleshooting issues in GitHub-managed CodeQL workflows, such as Default Setup. This setting can only be enabled by GitHub staff. #3485
  • Added a setting which enables GitHub-managed workflows, such as Default Setup, to use a nightly CodeQL CLI release instead of the latest, stable release that is used by default. This will help GitHub staff support customers whose analyses for a given repository or organization require early access to a change in an upcoming CodeQL CLI release. This setting can only be enabled by GitHub staff. #3484

v4.32.3

  • Added experimental support for testing connections to private package registries. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. #3466

v4.32.2

  • Update default CodeQL bundle version to 2.24.1. #3460

v4.32.1

  • A warning is now shown in Default Setup workflow logs if a private package registry is configured using a GitHub Personal Access Token (PAT), but no username is configured. #3422
  • Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. #3421
Changelog

Sourced from github/codeql-action's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.32.4 - 20 Feb 2026

  • Update default CodeQL bundle version to 2.24.2. #3493
  • Added an experimental change which improves how certificates are generated for the authentication proxy that is used by the CodeQL Action in Default Setup when private package registries are configured. This is expected to generate more widely compatible certificates and should have no impact on analyses which are working correctly already. We expect to roll this change out to everyone in February. #3473
  • When the CodeQL Action is run with debugging enabled in Default Setup and private package registries are configured, the "Setup proxy for registries" step will output additional diagnostic information that can be used for troubleshooting. #3486
  • Added a setting which allows the CodeQL Action to enable network debugging for Java programs. This will help GitHub staff support customers with troubleshooting issues in GitHub-managed CodeQL workflows, such as Default Setup. This setting can only be enabled by GitHub staff. #3485
  • Added a setting which enables GitHub-managed workflows, such as Default Setup, to use a nightly CodeQL CLI release instead of the latest, stable release that is used by default. This will help GitHub staff support customers whose analyses for a given repository or organization require early access to a change in an upcoming CodeQL CLI release. This setting can only be enabled by GitHub staff. #3484

4.32.3 - 13 Feb 2026

  • Added experimental support for testing connections to private package registries. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. #3466

4.32.2 - 05 Feb 2026

  • Update default CodeQL bundle version to 2.24.1. #3460

4.32.1 - 02 Feb 2026

  • A warning is now shown in Default Setup workflow logs if a private package registry is configured using a GitHub Personal Access Token (PAT), but no username is configured. #3422
  • Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. #3421

4.32.0 - 26 Jan 2026

  • Update default CodeQL bundle version to 2.24.0. #3425

4.31.11 - 23 Jan 2026

  • When running a Default Setup workflow with Actions debugging enabled, the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. #3409
  • Improved error handling throughout the CodeQL Action. #3415
  • Added experimental support for automatically excluding generated files from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. #3318
  • The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. #3403

4.31.10 - 12 Jan 2026

  • Update default CodeQL bundle version to 2.23.9. #3393

4.31.9 - 16 Dec 2025

No user facing changes.

4.31.8 - 11 Dec 2025

... (truncated)

Commits
  • 89a39a4 Merge pull request #3494 from github/update-v4.32.4-39ba80c47
  • e5d84c8 Apply remaining review suggestions
  • 0c20209 Apply suggestions from code review
  • 314172e Fix typo
  • cdda72d Add changelog entries
  • cfda84c Update changelog for v4.32.4
  • 39ba80c Merge pull request #3493 from github/update-bundle/codeql-bundle-v2.24.2
  • 00150da Add changelog note
  • d97dce6 Update default bundle to codeql-bundle-v2.24.2
  • 50fdbb9 Merge pull request #3492 from github/henrymercer/new-repository-properties-ff
  • Additional commits viewable in compare view

Updates docker/build-push-action from 6.18.0 to 6.19.2

Release notes

Sourced from docker/build-push-action's releases.

v6.19.2

Full Changelog: docker/build-push-action@v6.19.1...v6.19.2

v6.19.1

Full Changelog: docker/build-push-action@v6.19.0...v6.19.1

v6.19.0

Full Changelog: docker/build-push-action@v6.18.0...v6.19.0

Commits
  • 10e90e3 Merge pull request #1458 from crazy-max/git-auth-port
  • 5262538 chore: update generated content
  • cd130e4 preserve port in GIT_AUTH_TOKEN host
  • 806c751 Merge pull request #1452 from crazy-max/update-yarn
  • 601a80b Merge pull request #1456 from crazy-max/auth-token-dyn-host
  • 8f7fd7c chore: update generated content
  • 710e335 derive GIT_AUTH_TOKEN host from GitHub server URL
  • c4ca848 update yarn to 4.9.2
  • ee4ca42 Merge pull request #1398 from docker/dependabot/npm_and_yarn/tmp-0.2.4
  • f1b3bb5 chore: update generated content
  • Additional commits viewable in compare view

Updates anchore/scan-action from 7.3.1 to 7.3.2

Release notes

Sourced from anchore/scan-action's releases.

v7.3.2

⬆️ Dependencies

Commits
  • 7037fa0 chore(deps): bump @​actions/cache from 5.0.3 to 5.0.5 (#592)
  • d4c1dcd chore(deps): bump @​actions/tool-cache from 3.0.0 to 3.0.1 (#593)
  • d7f5518 chore(deps): update Grype to v0.107.1 (#594)
  • e573fa1 feat: add option to specify one or more grype config files (#589)
  • 4829fea chore(deps): bump fast-xml-parser from 5.3.3 to 5.3.4 (#590)
  • db5ac0e chore(deps): bump release-drafter/release-drafter from 6.1.0 to 6.2.0 (#587)
  • 5b5f7cd chore(deps): update Grype to v0.107.0 (#588)
  • 9fc81f9 chore(deps-dev): bump prettier from 3.8.0 to 3.8.1 (#584)
  • d2e46d3 chore(deps): bump peter-evans/create-pull-request from 8.0.0 to 8.1.0 (#585)
  • 1091f6b chore(deps-dev): bump tar from 7.5.6 to 7.5.7 (#586)
  • See full diff in compare view

Updates actions/attest-build-provenance from 3.2.0 to 4.1.0

Release notes

Sourced from actions/attest-build-provenance's releases.

v4.1.0

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.0.0...v4.1.0

v4.0.0

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v3.2.0...v4.0.0

Commits
  • a2bbfa2 bump actions/attest from 4.0.0 to 4.1.0 (#838)
  • 0856891 update RELEASE.md docs (#836)
  • e4d4f7c prepare v4 release (#835)
  • 02a49bd Bump github/codeql-action in the actions-minor group (#824)
  • 7c757df Bump the npm-development group with 2 updates (#825)
  • c44148e Bump github/codeql-action in the actions-minor group (#818)
  • 3234352 Bump @​types/node from 25.0.10 to 25.2.0 in the npm-development group (#819)
  • 18db129 Bump tar from 7.5.6 to 7.5.7 (#816)
  • 90fadfa Bump @​actions/core from 2.0.1 to 2.0.2 in the npm-production group (#799)
  • 57db8ba Bump the npm-development group across 1 directory with 3 updates (#808)
  • Additional commits viewable in compare view

Updates iarekylew00t/verified-bot-commit from 2.1.2 to 2.1.6

Release notes

Sourced from iarekylew00t/verified-bot-commit's releases.

v2.1.6

What's Changed

🏗️ Dependencies

Full Changelog: IAreKyleW00t/verified-bot-commit@v2.1.5...v2.1.6

v2.1.5

What's Changed

✨ Other Changes

🏗️ Dependencies

Full Changelog: IAreKyleW00t/verified-bot-commit@v2.1.4...v2.1.5

v2.1.4

What's Changed

🏗️ Dependencies

Full Changelog: IAreKyleW00t/verified-bot-commit@v2.1.3...v2.1.4

v2.1.3

What's Changed

✨ Other Changes

🏗️ Dependencies

... (truncated)

Commits
  • b001460 chore: Bumping version to v2.1.6
  • 87bfaef build(deps): Bump @​octokit/plugin-retry from 8.0.3 to 8.1.0 (#293)
  • 5b7bc78 build(deps): Bump minimatch from 10.2.3 to 10.2.4 (#297)
  • 508d8a5 build(deps): Bump minimatch from 10.2.2 to 10.2.3 (#296)
  • 1b47288 build(deps): Bump github/codeql-action from 4.32.3 to 4.32.4 in the actions g...
  • 45bbcde build(deps-dev): Bump the npm-development group with 4 updates (#291)
  • a2269b7 chore: Bumping version to v2.1.5
  • d9d9559 fix: Allow glob patterns to match dotfiles (#289)
  • 0e12e78 build(deps-dev): Bump the npm-development group with 4 updates (#285)
  • c723cf4 build(deps): Bump mi...

    Description has been truncated

Bumps the actions-deps group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.14.1` | `2.15.0` |
| [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `47.0.1` | `47.0.4` |
| [taiki-e/install-action](https://github.com/taiki-e/install-action) | `2.67.18` | `2.68.15` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `6.0.0` | `7.0.0` |
| [github/codeql-action](https://github.com/github/codeql-action) | `4.32.0` | `4.32.4` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `6.18.0` | `6.19.2` |
| [anchore/scan-action](https://github.com/anchore/scan-action) | `7.3.1` | `7.3.2` |
| [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `3.2.0` | `4.1.0` |
| [iarekylew00t/verified-bot-commit](https://github.com/iarekylew00t/verified-bot-commit) | `2.1.2` | `2.1.6` |
| [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.22.1` | `0.23.0` |


Updates `step-security/harden-runner` from 2.14.1 to 2.15.0
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@e3f713f...a90bcbc)

Updates `tj-actions/changed-files` from 47.0.1 to 47.0.4
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](tj-actions/changed-files@e002140...7dee1b0)

Updates `taiki-e/install-action` from 2.67.18 to 2.68.15
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@650c5ca...68675c5)

Updates `actions/upload-artifact` from 6.0.0 to 7.0.0
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@b7c566a...bbbca2d)

Updates `github/codeql-action` from 4.32.0 to 4.32.4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b20883b...89a39a4)

Updates `docker/build-push-action` from 6.18.0 to 6.19.2
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@2634353...10e90e3)

Updates `anchore/scan-action` from 7.3.1 to 7.3.2
- [Release notes](https://github.com/anchore/scan-action/releases)
- [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md)
- [Commits](anchore/scan-action@8d2fce0...7037fa0)

Updates `actions/attest-build-provenance` from 3.2.0 to 4.1.0
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@96278af...a2bbfa2)

Updates `iarekylew00t/verified-bot-commit` from 2.1.2 to 2.1.6
- [Release notes](https://github.com/iarekylew00t/verified-bot-commit/releases)
- [Commits](IAreKyleW00t/verified-bot-commit@a98e193...b001460)

Updates `anchore/sbom-action` from 0.22.1 to 0.23.0
- [Release notes](https://github.com/anchore/sbom-action/releases)
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md)
- [Commits](anchore/sbom-action@deef08a...17ae174)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-deps
- dependency-name: tj-actions/changed-files
  dependency-version: 47.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions-deps
- dependency-name: taiki-e/install-action
  dependency-version: 2.68.15
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-deps
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions-deps
- dependency-name: github/codeql-action
  dependency-version: 4.32.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions-deps
- dependency-name: docker/build-push-action
  dependency-version: 6.19.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-deps
- dependency-name: anchore/scan-action
  dependency-version: 7.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions-deps
- dependency-name: actions/attest-build-provenance
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions-deps
- dependency-name: iarekylew00t/verified-bot-commit
  dependency-version: 2.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions-deps
- dependency-name: anchore/sbom-action
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 1, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 1, 2026 12:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla: signed dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants